Risk
9/11/2013
04:30 PM
Connect Directly
RSS
E-Mail
50%
50%

Federal DDoS Warnings Are Outdated

We shouldn't be relying on sporadic government warnings about potential distributed denial of service attacks. Having a comprehensive DDoS plan already in place is security 101.

Iris Scans: Security Technology In Action
Iris Scans: Security Technology In Action
(click image for larger view)
It's always the same: Government cybersecurity experts learn of pending distributed denial of service attacks, especially around the anniversary of Sept. 11, and issue warning after warning after warning, as though security is something we can do on a "per-warning" basis.

I really don't understand this way of approaching security or why government agencies believe such warnings are helpful. I'm not saying we shouldn't be warned -- not at all. What I'm saying is that we shouldn't wait for a warning before we do something about security.

On Aug. 5, for instance, the FBI issued a warning that the same groups behind the unsuccessful Operations USA and Operation Israel attacks in May were planning a new DDoS attack. Their recommendations leave me perplexed. For instance, they suggest:

-- Implement backup and recovery plans. Really? We're supposed to wait for a warning on a 9/11 DDoS threat to know that we need to do this? We're in serious trouble if that's the case.

[ Yes, the National Security Agency snoops on cell phones. Here's how: NSA Vs. Your Smartphone: 5 Facts. ]

-- Scan and monitor emails for malware. Again, really? This is a recommendation? Is there truly anyone out there who still doesn't do this? And, if there is, they deserve whatever happens to their network, I say.

-- Outline DDoS mitigation strategies. Finally, something a bit more relevant. I know for a fact that most companies aren't putting much thought into DDoS defense strategy. Unfortunately, if you're hosting a server with public access, you've no choice but to consider this with the utmost seriousness. Just how seriously, you ask? Well, that all depends on how much of your company's livelihood hinges on that server.

It's an undeniable fact of our Internet life that these things will keep happening. No matter if it's 9/11 or OpUSA or a private single hacker from Russia or China. They'll continue to happen, and we all understand the need to be prepared.

DDoS preparedness is accomplished as a strategy. It involves hardware, large bandwidth, ISP collaboration, remote redundancy and other possible strategies for defense and elusion. This isn't anti-malware. You can't create a signature or heuristic against DDoS. This is sheer brute force in that you win if you're stronger, or if you're the more elusive, so they can't really get you.

And that's precisely why you need a strategy, and you need to plan it now. You can also purchase hardware -- but make it part of a strategy. Don't expect it to be the one and only thing you need to do to fend off a DDoS attack.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
solardalek
50%
50%
solardalek,
User Rank: Apprentice
9/16/2013 | 2:44:10 PM
re: Federal DDoS Warnings Are Outdated
>> DDoS warnings seem to fall in the same category of the color coded
terrorist alert warnings that DHS started issuing after 9/11. Some
action seems more defensible than no action.

You sure about that? Have you noticed that we've been in "orange" forever?

Rather than wait for some slow committee-driven alert, why not look for DDoS signs from your own systems? Get something like SolarWinds "Log & Event Manager", then watch for high alert traffic volumes or specific messages about IP lockouts, ridiculous connection attempts and other signals of an attack yourself.

To misquote Donnie from "Mystery Alaska": This is log analysis, OK? It's not rocket surgery."
WKash
50%
50%
WKash,
User Rank: Apprentice
9/12/2013 | 9:16:43 PM
re: Federal DDoS Warnings Are Outdated
DDoS warnings seem to fall in the same category of the color coded terrorist alert warnings that DHS started issuing after 9/11. Some action seems more defensible than no action.
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-2627
Published: 2014-08-01
Unspecified vulnerability in HP NonStop NetBatch G06.14 through G06.32.01, H06 through H06.28, and J06 through J06.17.01 allows remote authenticated users to gain privileges for NetBatch job execution via unknown vectors.

CVE-2014-3009
Published: 2014-08-01
The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 does not properly handle FRAME elements, which makes it easier for remote authenticated users to conduct ph...

CVE-2014-3302
Published: 2014-08-01
user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the token timer for authenticated encryption, which allows remote attackers to obtain sensitive information via a crafted URL, aka Bug ID CSCuj81708.

CVE-2012-6651
Published: 2014-07-31
Multiple directory traversal vulnerabilities in the Vitamin plugin before 1.1.0 for WordPress allow remote attackers to access arbitrary files via a .. (dot dot) in the path parameter to (1) add_headers.php or (2) minify.php.

CVE-2014-2970
Published: 2014-07-31
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-5139. Reason: This candidate is a duplicate of CVE-2014-5139, and has also been used to refer to an unrelated topic that is currently outside the scope of CVE. This unrelated topic is a LibreSSL code change adding functionality ...

Best of the Web
Dark Reading Radio